Skip to Main Content
Access control is an important security issue for the web. However, exiting methods still have some limitations. Most of them can not satisfy the requirements of loosely-coupled and fine-grained access control at the same time. This paper addresses this issue for web information system by proposing a novel access control method based on HTTP data stream filtration. It is loosely-coupled with web information system, so it is flexible and can be used in different web information systems. By the element-level resources identification algorithm we proposed, it also can achieve fine-grained access control for web page resources. In the end, the analysis of our algorithm is given. The results show that our algorithm is effective and the time-consuming is tolerable.